CVE-2020-7067
PoC —CVSS 3.1
7.5 high
EPSS
4%p91
Published
()
Modified
Description
In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
In the news0 stories
No ingested article mentions this CVE yet.